Windows凭据提供者无法调整登录权限问题求助
Windows Credential Provider权限设置问题:无法启用SE_INCREASE_QUOTA_NAME和SE_ASSIGNPRIMARYTOKEN_NAME
我正在开发Windows Credential Provider,需要编程实现用户登录,但在设置SE_INCREASE_QUOTA_NAME和SE_ASSIGNPRIMARYTOKEN_NAME权限时遇到问题。即使添加了要求管理员权限的清单文件并以管理员身份运行应用,仍提示令牌无指定权限,错误码1300。
相关代码
SetPrivilege函数
BOOL SetPrivilege( HANDLE hToken, // token handle LPCTSTR Privilege, // Privilege to enable/disable BOOL bEnablePrivilege // TRUE to enable. FALSE to disable ) { TOKEN_PRIVILEGES tp; LUID luid; if (!LookupPrivilegeValue( NULL, // lookup privilege on local system Privilege, // privilege to lookup &luid)) // receives LUID of privilege { logFile << "LookupPrivilegeValue Error: " << GetLastError() << std::endl; return FALSE; } tp.PrivilegeCount = 1; tp.Privileges[0].Luid = luid; tp.Privileges[0].Attributes = (bEnablePrivilege) ? SE_PRIVILEGE_ENABLED : 0; // Enable the privilege or disable all privileges. if (!AdjustTokenPrivileges( hToken, FALSE, &tp, sizeof(TOKEN_PRIVILEGES), (PTOKEN_PRIVILEGES)NULL, (PDWORD)NULL)) { logFile << "AdjustTokenPrivileges error: " << GetLastError() << std::endl; return FALSE; } if (GetLastError() == ERROR_NOT_ALL_ASSIGNED) { logFile << "The token does not have the specified privilege: " << Privilege << std::endl; return FALSE; } logFile << "Successfully adjusted the privilege: " << Privilege << std::endl; return TRUE; }
PerformLogin函数
HRESULT CSampleCredential::PerformLogin() { const wchar_t* username = L"username"; //hardcoded const wchar_t* password = L"password"; //hardcoded const wchar_t* domain = L"."; // Local machine HANDLE hToken = NULL; BOOL success = LogonUser( username, domain, password, LOGON32_LOGON_INTERACTIVE, LOGON32_PROVIDER_DEFAULT, &hToken ); HRESULT hr = S_OK; if (success) { HANDLE hCurrentToken; if (OpenProcessToken(GetCurrentProcess(), TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, &hCurrentToken)) { BOOL priv1 = SetPrivilege(hCurrentToken, SE_INCREASE_QUOTA_NAME, TRUE); BOOL priv2 = SetPrivilege(hCurrentToken, SE_ASSIGNPRIMARYTOKEN_NAME, TRUE); BOOL privSet = priv1 && priv2; logFile << "priv1 returns: " << priv1 << std::endl; logFile << "priv2 returns: " << priv2 << std::endl; if (privSet) { logFile << "Privileges set successfully." << std::endl; //…………………. // Revert the privilege change SetPrivilege(hCurrentToken, SE_INCREASE_QUOTA_NAME, FALSE); SetPrivilege(hCurrentToken, SE_ASSIGNPRIMARYTOKEN_NAME, FALSE); } else { DWORD error = GetLastError(); logFile << "Failed to set required privileges with error code: " << error << std::endl; hr = HRESULT_FROM_WIN32(error); } CloseHandle(hCurrentToken); } else { DWORD error = GetLastError(); logFile << "OpenProcessToken failed with error code: " << error << std::endl; hr = HRESULT_FROM_WIN32(error); } CloseHandle(hToken); } else { DWORD error = GetLastError(); logFile << "LogonUser failed with error code: " << error << std::endl; hr = HRESULT_FROM_WIN32(error); } return hr; }
日志信息
The token does not have the specified privilege: 00007FFC40D3FF98 The token does not have the specified privilege: 00007FFC40D3FFD8 priv1 returns: 0 priv2 returns: 0 Failed to set required privileges with error code: 1300
已添加的清单文件
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges> <requestedExecutionLevel level="requireAdministrator" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
已尝试操作
- 验证mt.exe已正确嵌入清单
- 确保应用以高权限运行
- 确认app.manifest已正确加入项目
环境信息
- 操作系统:Windows 11
- Visual Studio版本:Visual Studio 2022
- 项目类型:原生C++ DLL
求助
如何成功设置所需权限以实现用户登录并在其会话中创建进程?
内容的提问来源于stack exchange,提问作者user13347928
相关产品推荐
相关产品推荐

